Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c. | |
| Title | Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload Validation | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T21:58:01.174Z
Reserved: 2026-08-19T21:47:08.936Z
Link: CVE-2026-76870
No data.
Status : Received
Published: 2026-09-15T22:17:02.030
Modified: 2026-09-15T22:17:02.030
Link: CVE-2026-76870
No data.
OpenCVE Enrichment
No data.
-
CWE-125
Out-of-bounds Read